dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003a

This is an old revision of the document!


OR-003a — Classified Environment Operations

Crucible SHALL execute each selected Operational Lifecycle activity within a Classified Environment.

This requirement derives from:

The Original Requirement states:

The system SHALL support classified and unclassified deployment environments.[C1]

OR-003a isolates the obligation to execute Operational Lifecycle activities within a Classified Environment from the separate obligation to execute those activities within an Unclassified Environment.

A Classified Environment imposes authorization, access, information-handling, transfer, auditing, and operational constraints that can differ from those governing an Unclassified Environment.

Crucible must execute its selected Operational Lifecycle activities within those constraints rather than treating classified operation as an extension of ordinary deployment.

Selected Operational Lifecycle activities can include:

  • Description retrieval
  • Baseline composition
  • Dependency acquisition or import
  • Machine Image construction
  • Security hardening
  • Compliance assessment
  • Infrastructure Deployment
  • Deployment Validation
  • Evidence generation
  • Maintenance
  • Update
  • Cross-Domain Transfer
  • Retirement

The governing requirements for a Classified Environment can depend on:

OR-003a establishes the requirement to execute the selected activities within a Classified Environment. Separate requirements govern Security Domain enforcement, Information Handling Rule enforcement, Cross-Domain Transfer control, and access control.

Verification confirms that:

  1. The tested environment is an authorized Classified Environment
  2. The tested Classified Environment identifies the Security Classifications it is authorized to handle
  3. The tested Classified Environment identifies its governing Security Domain
  4. The selected Operational Lifecycle activities are identified before execution
  5. Crucible initiates each selected Operational Lifecycle activity within the Classified Environment
  6. Crucible completes each selected Operational Lifecycle activity that satisfies its initiation and execution conditions
  7. Crucible records the result of each selected Operational Lifecycle activity
  8. Crucible records any activity it rejects, blocks, or terminates
  9. Each activity record identifies the Classified Environment in which execution occurred
  10. Each activity record identifies the governing Security Domain
  11. Each activity record preserves Auditability, Provenance, and Traceability

Determine the Delivery Phase for OR-003a.

Assess whether the current Crucible implementation executes the selected Operational Lifecycle activities within an authorized Classified Environment.

Review and approve OR-003a as a leaf requirement derived from OR-003.


Define the Operational Lifecycle activities that Crucible must execute within each supported Classified Environment.

Identify the Security Classifications that each supported Classified Environment is authorized to handle.

Identify the Classification Authority governing each supported Classified Environment.

Define the Security Domain governing each supported Classified Environment.

Define the conditions for initiating, completing, rejecting, blocking, or terminating each selected Operational Lifecycle activity.

Define the records and Evidence required for each selected Operational Lifecycle activity.

Define the acceptance criteria for successful execution within each supported Classified Environment.


This requirement page should retain the stable requirement identifier OR-003a.

This page is a leaf requirement page and omits a trailing :start from its namespace.

OR-003a addresses execution of selected Operational Lifecycle activities within a Classified Environment.

Separate child requirements address:

  • Unclassified Environment operations
  • Security Domain enforcement
  • Information Handling Rule enforcement
  • Cross-Domain Transfer control
  • Security Domain access control

Changes to the Statement should preserve:

  • Crucible as the responsible actor
  • Execution as the required behavior
  • Each selected Operational Lifecycle activity as the subject of execution
  • A Classified Environment as the operating context

To reference this requirement Statement from another wiki page, insert:

{{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003a#Statement&noheader&nofooter&noeditbtn}}

Do not rename this page after an external citation unless a redirect or move plan is in place.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/02-crusible/99-annexes/annex-c-requirements/02-operational-requirements/or-003/or-003a.1784824807.txt.gz
  • Last modified: 2026/07/23 09:40
  • by nick_dido